Hand an AI-tool connection to engineering.
For a site owner, this catalogue answers two questions: what an approved AI client can ask GymCore to do, and which requests can read personal data or change a customer record. If you are not connecting an external AI tool, no customer setup is required here.
Engineers call this connection MCP (Model Context Protocol). GymCore registers WordPress “abilities”—named operations with input rules, output rules, and a permission check—and an installed MCP adapter can expose approved abilities to an authenticated client. “Public” adapter metadata means discoverable to that authenticated client, not anonymous internet access.
Inventory count: 39 source inventory rows: 37 concrete core ability names, one dynamic GymCore AI tool family, and one runtime-validation marker. The dynamic family expands from the installed AI tool registry. Registration is not a public support guarantee; verify the installed version, permission callback, schema, and side effects before integration.
Security contract
- Use HTTPS and authenticated WordPress credentials or the explicitly supported integration signature.
- Give service accounts only the named WordPress permission required by the route or ability. Engineers call that permission a capability.
- Never place application passwords, tokens, or webhook secrets in browser code, URLs, screenshots, or this documentation.
- The visible General > REST API switch does not gate registered routes in the audited source.
- Treat GET/read responses as personal data when they contain members, attendance, ranks, leads, messages, or finance.
- Treat POST/write calls as potentially irreversible; implement idempotency and verify the source record after each request.
Registered catalogue
| Stable ID | Item / route | Source | Audience | Prerequisites | Registered path | Risk and side effect |
|---|---|---|---|---|---|---|
| INV-MCP-0001 | Dynamic gandalf/<tool-name> family |
wp-content/plugins/gym-core-ai/src/MCP/AbilitiesRegistrar.php:166 |
operator/developer/integration client | WordPress Abilities API; installed AI ToolRegistry; MCP adapter for external discovery | One ability per installed tool name, normalized to kebab case | Read tools are discoverable by default; write tools remain hidden from MCP discovery unless an operator explicitly exposes them, and still pass persona, permission, and approval gates |
| INV-MCP-0002 | AI MCP runtime validation marker | wp-content/plugins/gym-core-ai/src/Runtime/AiMcpRuntimeValidator.php:113 |
operator/developer | Installed WordPress Abilities API and adapter | No standalone ability name; validates runtime availability | Diagnostic only; do not call it as an ability or count it as a concrete customer operation |
| INV-MCP-0003 | gym-members/list | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:64 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-members/list | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0004 | gym-members/get | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:97 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-members/get | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0005 | gym-members/meta | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:120 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-members/meta | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0006 | gym-members/update-meta | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:143 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-members/update-meta | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0007 | gym-members/parent-portal | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:171 |
member/parent or public visitor | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-members/parent-portal | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0008 | gym-attendance/check-in | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:207 |
coach/head coach/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-attendance/check-in | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0009 | gym-attendance/history | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:238 |
coach/head coach/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-attendance/history | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0010 | gym-attendance/today | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:263 |
coach/head coach/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-attendance/today | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0011 | gym-attendance/milestones | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:284 |
coach/head coach/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-attendance/milestones | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0012 | gym-schedule/list-classes | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:320 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-schedule/list-classes | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0013 | gym-schedule/weekly | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:342 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-schedule/weekly | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0014 | gym-schedule/roster | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:367 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-schedule/roster | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0015 | gym-schedule/waitlist | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:390 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-schedule/waitlist | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0016 | gym-ranks/get-rank | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:426 |
coach/head coach/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-ranks/get-rank | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0017 | gym-ranks/rank-history | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:453 |
coach/head coach/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-ranks/rank-history | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0018 | gym-ranks/promote | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:476 |
coach/head coach/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-ranks/promote | high: mutates data, sends communication, or crosses trust boundary |
| INV-MCP-0019 | gym-ranks/belt-systems | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:509 |
coach/head coach/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-ranks/belt-systems | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0020 | gym-sales/products | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:538 |
sales/front desk/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-sales/products | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0021 | gym-sales/create-order | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:559 |
sales/front desk/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-sales/create-order | high: mutates data, sends communication, or crosses trust boundary |
| INV-MCP-0022 | gym-sales/walk-in | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:590 |
sales/front desk/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-sales/walk-in | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0023 | gym-sales/billing | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:622 |
finance/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-sales/billing | medium-high: sensitive access/configuration |
| INV-MCP-0024 | gym-gamification/badges | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:658 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-gamification/badges | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0025 | gym-gamification/member-badges | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:679 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-gamification/member-badges | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0026 | gym-gamification/streak | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:702 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-gamification/streak | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0027 | gym-gamification/foundations | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:725 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-gamification/foundations | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0028 | gym-reports/list | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:761 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-reports/list | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0029 | gym-reports/run | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:777 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-reports/run | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0030 | gym-reports/heatmap | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:800 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-reports/heatmap | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0031 | gym-reports/analytics | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:829 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-reports/analytics | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0032 | gym-sms/send | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:863 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-sms/send | high: mutates data, sends communication, or crosses trust boundary |
| INV-MCP-0033 | gym-sms/templates | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:891 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-sms/templates | high: mutates data, sends communication, or crosses trust boundary |
| INV-MCP-0034 | gym-sms/conversations | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:907 |
operator/developer/integration client | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-sms/conversations | high: mutates data, sends communication, or crosses trust boundary |
| INV-MCP-0035 | gym-leads/list | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:943 |
sales/front desk/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-leads/list | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0036 | gym-leads/get | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:970 |
sales/front desk/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-leads/get | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0037 | gym-leads/create | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:993 |
sales/front desk/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-leads/create | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0038 | gym-leads/move-stage | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:1026 |
sales/front desk/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-leads/move-stage | medium: authenticated/operator surface; permission and side effects vary |
| INV-MCP-0039 | gym-leads/funnel | wp-content/plugins/gym-core/src/MCP/GymAbilities.php:1054 |
sales/front desk/admin | WordPress Abilities API; MCP adapter for external MCP; authenticated capability as defined | registered mcp-ability gym-leads/funnel | medium: authenticated/operator surface; permission and side effects vary |
Integration checklist
- Pin the installed GymCore/GymCore AI version you tested.
- Confirm exact method, namespace, request schema, permission callback, and response schema in source.
- Test authentication failure, capability failure, invalid input, empty result, duplicate/retry, and timeout behavior on staging.
- Redact logs and set retention for request/response payloads.
- For mutations, use a unique idempotency key where supported or an application-side deduplication record.
- Verify the WordPress/GymCore/WooCommerce source record and downstream provider after every write.
- Document credential owner, rotation date, allowed IPs, incident response, and removal procedure.
Related guides
Need help?
Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.